September 15, 2017 By Shane Schick 2 min read

Approximately 200,000 websites running WordPress have been affected by a malware attack from a plug-in that installed a backdoor, allowing a malicious actor to publish spam, collect IP addresses and more.

Wordfence, a security firm that focuses on the popular content management system, said in a blog post that the malware attack has been traced to a plug-in called Display Widgets, which was purportedly designed to manage the way other plug-ins are displayed on WordPress sites. Though it has recently been removed, the threat actor behind the malicious activity did not give up easily.

According to SecurityWeek, the original creator of Display Widgets sold it in late June, after which it was almost immediately updated with a backdoor. David Law, a freelance SEO consultant, noticed the initial malware attack and informed Wordfence, which removed it from the WordPress plug-in repository.

Just a few days later, however, Display Widgets emerged again, this time with an additional file called geolocation.php that could perform the same kind of malware attack, Bleeping Computer reported. When site owners looked at their WordPress admin panels, though, the malicious content was invisible; again, Law detected the malicious activity by tracking visits to an external server by the plug-in.

History then seemed to repeat itself in July and even earlier this month, an article on SC Magazine said, with the Display Widgets owner even making it obvious that the plug-in was being refined to continue launching the same kind of malware attack. In total, the plug-in was made available at least four times before it was pulled for good.

Law has since published his own account of the Display Widgets story. In the post, he provided an overview of the various versions involved and suggested deleting the plug-in. WordPress, meanwhile, banned the developer from its platform following the malware attack and issued critical alerts each time Display Widgets was removed.

Though the extent of the damage may have been limited to spamming various websites, the story illustrates how persistent cybercriminals can be, even in the face of repeated retaliatory action by companies the size of WordPress. It’s also a cautionary tale about the relative ease with which plug-ins can be bought, sold and repurposed for uses the original creators probably never would have imagined.

More from

SoaPy: Stealthy enumeration of Active Directory environments through ADWS

10 min read - Introduction Over time, both targeted and large-scale enumeration of Active Directory (AD) environments have become increasingly detected due to modern defensive solutions. During our internship at X-Force Red this past summer, we noticed FalconForce’s SOAPHound was becoming popular for enumerating Active Directory environments. This tool brought a new perspective to Active Directory enumeration by performing collection via Active Directory Web Services (ADWS) instead of directly through Lightweight Directory Access Protocol (LDAP) as other AD enumeration tools had in the past.…

Smoltalk: RCE in open source agents

26 min read - Big shoutout to Hugging Face and the smolagents team for their cooperation and quick turnaround for a fix! Introduction Recently, I have been working on a side project to automate some pentest reconnaissance with AI agents. Just after I started this project, Hugging Face announced the release of smolagents, a lightweight framework for building AI agents that implements the methodology described in the ReAct paper, emphasizing reasoning through iterative decision-making. Interestingly, smolagents enables agents to reason and act by generating…

4 ways to bring cybersecurity into your community

4 min read - It’s easy to focus on technology when talking about cybersecurity. However, the best prevention measures rely on the education of those who use technology. Organizations training their employees is the first step. But the industry needs to expand the concept of a culture of cybersecurity and take it from where it currently stands as an organizational responsibility to a global perspective.When every person who uses technology — for work, personal use and school — views cybersecurity as their responsibility, it…

Topic updates

Get email updates and stay ahead of the latest threats to the security landscape, thought leadership and research.
Subscribe today